Vulnerability Disclosure Policy

Mika places the highest priority on the security and privacy of our information systems to safeguard our customers' and employees' data.
As of 23 July 2025

The vulnerability disclosure policy has been established to provide security researchers with clear guidelines for responsibly conducting vulnerability discovery activities on Mika's apps, systems and websites. It also outlines the procedures for submitting identified vulnerabilities to Mika.

This page specifies the systems and types of research covered under this program, the process for submitting vulnerability reports, and the requirements for the disclosure of submitted vulnerabilities.

If you identify a security vulnerability within our information systems, please refer to the information provided below for guidance on submitting a disclosure.

Scope

The following apps, websites and their subdomains are in scope for the vulnerability disclosure policy program.

List of websites in scope

www.mikapaytech.com

www.mikatap.com

www.mikaflex.com

portal.mikapaytech.com

portal.mikatap.com

portal.mikaflex.com

sign-up.mikapaytech.com

sign-up.mikatap.com

sign-up.mikaflex.com

List of apps in scope

Mika Giving App

Mika Tap App

Mika Terminal App

Mika Flex App

If you discover a domain that is not included in the above list but you believe it may be owned by Mika, please send your query to security@mikatap.com. We will inform you if the domain is in scope of the vulnerability disclosure policy program.

Out of scope

The following are out of scope for the vulnerability disclosure policy program:

Guidance

These guidelines are designed to help both you and Mika when you find a security issue with our systems. If you're doing security testing, please:

Reporting a vulnerability

Please report your findings to security@mikapaytech.com By emailing or providing a disclosure to us, you agree that we can use your submission and its contents to ensure the security, integrity, and reliable operation of our technology and business.

If you're uncomfortable sending any of the following content by email, you may mask or redact sensitive content. If you want to encrypt data using the PGP key, email security@mikapaytech.com and ask for one.

Please include the following information in your disclosure:

What to expect

Upon receiving a vulnerability disclosure, we will take the following steps: